CVE-2026-47831: Cryptographically Weak Password Generation in bosh-windows-stemcell-builder Allows Remote SSH Brute-Force Attacks
Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
bosh-windows-stemcell-builderto a version that resolves this vulnerability.Fixed in v2019.98 - Compensating control
Restrict remote SSH (TCP/22) access to the bosh-windows-stemcell-builder instances to prevent brute-force attempts against the generated SSH credentials.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47831?
CVE-2026-47831 has a severity rating of high with a score of 7.5.
How do I fix CVE-2026-47831?
To fix CVE-2026-47831, upgrade bosh-windows-stemcell-builder to version v2019.98 or later.
What type of attacks can result from CVE-2026-47831?
CVE-2026-47831 allows remote attackers to perform brute-force SSH attacks on the affected system.
Which software is affected by CVE-2026-47831?
CVE-2026-47831 affects bosh-windows-stemcell-builder versions prior to v2019.98.
What is the impact of CVE-2026-47831?
The impact of CVE-2026-47831 is the potential unauthorized access to systems via weak SSH passwords.